Fastmail offers EU data region
Fastmail’s new EU data region for email hosting is welcomed by many European users but heavily scrutinized for its practical privacy impact. Commenters note that while Fastmail runs its own servers in Amsterdam, backups and replicas still reside in the US and the Australian company remains subject to Five Eyes intelligence sharing and CLOUD Act–style data access, so it cannot guarantee data will stay solely within the EU or beyond reach of US and Australian authorities. The broader debate centers on data sovereignty, the limits of “EU region” marketing, and whether true privacy requires end‑to‑end encryption and EU‑only providers with no US or Five Eyes exposure.
Infrastructure & What the New EU Region Actually Does
- Fastmail has deployed its own hardware in a colocation facility in Amsterdam, not on AWS/Azure/GCP.
- Data is encrypted at rest, managed in‑house, similar to their US sites (Philadelphia, St. Louis).
- For now, “resilient replicas” and emergency backups for all users still live in the US; logs are also not clearly EU‑only.
- Fastmail explicitly states it cannot guarantee data will remain solely in the EU; some see this as honest, others as undercutting the value of the feature.
Legal Jurisdiction, CLOUD Act, and Five/Nine/Fourteen Eyes
- Many argue the main risk is jurisdiction, not physical location.
- Because Fastmail is Australian (a Five Eyes country) and Australia has a bilateral CLOUD Act agreement and its own Assistance and Access Act, several commenters claim US/AU authorities can still compel access, potentially with gag orders.
- Others contest the exact reach and enforceability of CLOUD Act–style agreements across borders, pointing to conflicts with EU laws and “blocking statutes,” but agree situations can become complex.
- Some call this “sovereignty washing”: marketing EU data regions while core legal exposure (Five Eyes, CLOUD Act) remains unchanged.
Email Security and Threat Models
- Strong consensus that email is inherently weak for privacy: metadata is exposed, E2E is rare, and cross‑provider traffic (e.g., to Gmail) undermines any single provider’s protections.
- Several advise using end‑to‑end encrypted messengers for sensitive content and treating email mainly as communication + archival.
- Jurisdiction and infrastructure choices are framed as “defense in depth” rather than a full solution.
Customer Reactions
- Some EU users are pleased: lower latency, “closer to home” storage, and symbolic alignment with EU sovereignty.
- Others see little practical benefit until there are multiple EU data centers and EU‑only backups.
- A subset says they would avoid any provider under US/Five Eyes influence altogether.
Alternatives and Euro “Sovereign” Options
- Multiple EU‑centric providers are mentioned (e.g., mailbox.org, Posteo, Runbox, Migadu, Tuta, Infomaniak) and curated lists of European alternatives.
- Broader trend noted: EU companies and governments exploring “EuroStack” / sovereign clouds and moving away from US hyperscalers, though many still rely heavily on them.